Security & Compliance
Last updated: September 10, 2026
SurgiMD handles some of the most sensitive data there is: identifiable clinical photography. This page describes the technical and organisational measures behind the app, and how they map to the major data-protection frameworks our users work under.
GDPR (European Union)
SurgiMD is designed to support GDPR-compliant use by clinics:
- Roles done right: your clinic is the data controller; SurgiMD acts as a processor on your instructions. A Data Processing Agreement (DPA) is available for clinics on request.
- Lawful basis & explicit consent: health data is special-category data (Art. 9). SurgiMD's per-patient, versioned consent capture gives clinics an auditable record of explicit consent.
- Data-subject rights: patient records are exportable and erasable on request, supporting access and erasure obligations.
- Security of processing (Art. 32): encryption, access control, audit logging and de-identification as described above.
HIPAA (United States)
SurgiMD is built on HIPAA-eligible infrastructure and implements the technical safeguards the Security Rule expects:
- Unique user authentication, automatic screen lock, and role-based access
- Encryption of ePHI in transit and at rest
- Integrity controls via the tamper-evident audit log
- Consent-gated disclosure controls and de-identification tooling
- Business Associate Agreements (BAAs) are available to covered entities on request.
We say “designed to support HIPAA compliance” deliberately: there is no such thing as HIPAA certification, and any vendor claiming one is telling you something about their marketing, not their engineering.
Dubai Health Authority & UAE health data law
SurgiMD is built in the UAE, for UAE clinicians first — and we take the local framework seriously, including Federal Law No. 2 of 2019 (ICT in Health Fields), the DHA's health data protection requirements, and Dubai's health data legislation:
- The safeguards above — encryption, access control, consent, audit, de-identification — map directly to DHA expectations for patient confidentiality and record integrity.
- Clinicians retain full control of where exports go; nothing leaves the app without an explicit, logged, consent-checked action.
- Data residency: we are transparent that cloud data is currently hosted on secure Google Cloud infrastructure outside the UAE, and we are working toward regional hosting options for clinics that require in-country storage. Clinics with strict residency mandates can operate SurgiMD fully on-device (local-only mode) today.
The shared-responsibility model, plainly
SurgiMD gives your practice the technical safeguards; compliance is a partnership. Your clinic remains responsible for its own policies — obtaining patient consent, training staff, and using exports appropriately. We give you the tools that make doing the right thing the default: consent gates, de-identification, audit trails and locked-down storage.